Senior Cloud & Infrastructure Engineer/E-ITSCO Manager
hace 2 días
Herndon
Job Description The Senior Cloud & Infrastructure Engineer / E-ITSCO Manager is responsible for leading ISI’s internal IT, cloud, and security operations across three business units — Managed Services (MSP/MSSP), Industrial Security Services, and SaaS Platform Operations. This role ensures Confidentiality, Integrity, and Availability (CIA) of corporate systems and data while maintaining compliance with CMMC 2.0 Level 2, NIST 800-171 R2, FedRAMP-Moderate, and DFARS 252.204-7012 requirements. The role blends hands-on engineering (Microsoft 365, Azure, AWS, hybrid infrastructure) with strategic leadership, overseeing internal IT operations, security alignment, vendor management, and compliance integration. The incumbent will build and lead a small high-performing team to deliver secure, reliable, and scalable enterprise IT services. Key Responsibilities Leadership & Department Management • Lead and manage the E-ITSCO department, including internal IT, cloud, and infrastructure operations., • Oversee Tier 1 / Tier 2 support, set priorities, and ensure SLA adherence for 170+ internal users., • Mentor technical staff, conduct performance reviews, and establish career development plans., • Manage vendor relationships, licensing, and procurement for hardware, software, and SaaS services., • Develop and track department KPIs (uptime, incident response, compliance readiness, satisfaction)., • Serve as escalation point for all internal IT and infrastructure issues. Cloud & Infrastructure Engineering • Architect, deploy, and maintain secure hybrid environments spanning Azure, AWS (GovCloud), Rapid7 and on-prem systems., • Enforce CIS / DISA STIG baselines and maintain compliant configurations., • Manage Azure AD / Entra ID, Group Policy, Intune, Conditional Access, and device compliance., • Oversee network segmentation, firewalls, VPN, DNS/DHCP, and hybrid connectivity (ExpressRoute, Direct Connect)., • Implement infrastructure-as-code (Terraform/Bicep) and maintain CI/CD pipelines for secure provisioning., • Maintain patching, backups, DR testing, and system documentation (CMDB, topology diagrams). Security & Compliance Integration • Collaborate with the Cybersecurity and Compliance departments to align internal operations with CMMC, NIST 800-171, and FedRAMP Moderate control objectives., • Maintain SSPs, POA&Ms, and audit evidence for infrastructure and IT controls (families 3.1 – 3.14), • Oversee vulnerability management, logging, and audit trail integrity (e.g., Sentinel, Defender for Cloud, Rapid7 security Tools), • Implement endpoint protection, data loss prevention, and encryption policies for systems containing PII or CUI., • Participate in annual self-assessments, mock audits, and tabletop exercises. Governance, Risk & Process Management • Chair the Change Control Board (CCB); enforce ITIL Incident/Problem/Change workflows., • Own internal IT policies, SOPs, and asset inventory; ensure quarterly review and version control., • Lead risk assessments and business continuity planning; maintain recovery point/time objectives., • Coordinate with Finance, HR, and PMO for cross-departmental systems integration and data governance. Qualifications This position requires applicants to have current, interim eligibility or previous security clearance. • Candidates must have held or currently hold a clearance, or have documented eligibility based on a favorable background investigation., • Interim clearances will be accepted for consideration., • All clearances are encouraged to apply., • U.S. citizenship is required by federal regulation., • Applicants without any of the above will not be considered at this time due to contract requirements., • Bachelor’s degree in Computer Science, Information Technology, or related field (or equivalent experience), • 7+ years in IT infrastructure and cloud administration, with 3+ years in a leadership or team-lead role, • Experience supporting regulated or federal environments (DoD, DIB, or FedRAMP), • Microsoft Certified: Azure Administrator Associate or Enterprise Administrator, • AWS Certified: SysOps Administrator or Solutions Architect – Associate, • CompTIA Security+, • ITIL Foundation Secondary (Recommended) Certifications, • CISSP or CISM, • Microsoft Certified: Azure Security Engineer Associate, • AWS Security Specialty • Strategic planning, budgeting, and KPI management, • Team mentorship and performance management, • Executive-level communication and cross-department collaboration, • Change leadership and incident command during major events PII Acumen • Implements encryption, access controls, and privacy-by-design frameworks., • Ensures PII/CUI handling aligns with DFARS and DoD data governance policies. Network Acumen • Designs segmented, secure networks with defense-in-depth principles., • Administers firewalls, routing, VPNs, and MFA-secured remote access. CMMC & NIST 800-171 Acumen • Maintains alignment for infrastructure-related controls (3.1–3.14)., • Supports evidence collection for SPRS scoring and audit preparation. Process Management • Establishes, audits, and continuously improves ITIL processes., • Documents and enforces SOPs, runbooks, and change workflows., • Leads quarterly process reviews and lessons-learned retrospectives. What we offer: • The salary range for this role is $140,000-$170,000 commensurate with experience, • Hybrid work - 2 days in office (Herndon, VA), • A competitive salary and benefits package, • A casual, friendly, and relaxed work environment, • Professional growth encouragement and supportIndustrial Security Integrators, LLC (“IsI”) is an equal opportunity employer committed to affirmative action and diversity in the workplace. It is the policy of IsI to provide Equal Employment Opportunities (EEO) to Employees and Applicants, without regard to race, color, religion, sex, age, marital status, citizenship status, national origin, sexual orientation, gender identity, veteran status or disability or any other factor protected by law and to provide advancement opportunities for minorities, women, disabled individuals, and veterans. IsI is stronger and more effective when our workforce includes highly qualified individuals with diverse backgrounds, cultures, and traditions. IsI Enterprises does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job postings or otherwise. Placement fees will not be paid to any recruiter unless IsI has an active agreement in place with the recruiter and such a request has been made by the IsI hiring team and such candidate was submitted to the IsI hiring team via our Applicant Tracking System. Any unsolicited resumes or other data submitted to IsI in violation of this policy may be used by IsI without obligation to pay any fees of any kind to the recruiter. Powered by JazzHR nO2xwMLZfq